GitHub Security Advisories
Open-source package ecosystem coverage across npm / PyPI / Maven / Go / RubyGems and more.
21,414 advisories tracked · showing 100
- Jul 22, 2026GHSA-vhcw-f978-xjjgHighCVE-2026-65597
n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site...
- Jul 22, 2026GHSA-6mxq-jr92-3h2rMediumCVE-2026-65601
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the...
- Jul 22, 2026GHSA-7m3p-wc52-rmc6MediumCVE-2026-65602
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces...
- Jul 22, 2026GHSA-rhg6-2vjh-j5qcHighCVE-2026-65600
Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an...
- Jul 22, 2026GHSA-38mm-mxvc-j98qHighCVSS 8.8CVE-2026-65603
The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw...
- Jul 22, 2026GHSA-725q-c4vp-q4cgHighCVE-2026-65598
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone...
- Jul 22, 2026GHSA-mhvh-gwhr-76pwMediumCVE-2026-65599
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability:...
- Jul 22, 2026GHSA-qv24-466w-wgvjHighCVSS 7.2CVE-2026-61391
There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow...
- Jul 22, 2026GHSA-fmvg-vhqq-r2mjMediumCVE-2026-65589
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node...
- Jul 22, 2026GHSA-m7jc-p4hf-xhwqHighCVE-2026-65591
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed...
- Jul 22, 2026GHSA-5vfw-jc4p-fj39MediumCVE-2026-65594
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and...
- Jul 22, 2026GHSA-wq64-hcrf-8m56HighCVE-2026-65595
n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token...
- Jul 22, 2026GHSA-fggv-cfcv-qhcfMediumCVSS 5.3CVE-2026-61392
There is a information disclosure vulnerability in some Hikvision cameras, allowing...
- Jul 22, 2026GHSA-gr8g-8h3g-v65pHighCVSS 7.5CVE-2026-57600
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows...
- Jul 22, 2026GHSA-mwq7-vcmc-cm4qHighCVE-2026-65016
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in...
- Jul 22, 2026GHSA-xfrr-5gjq-c74jMediumCVSS 6.6CVE-2026-57599
There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect...
- Jul 22, 2026GHSA-38fj-36m5-783cMediumCVE-2026-65593
n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic...
- Jul 22, 2026GHSA-739w-7wq3-9vffHighCVSS 7.7CVE-2026-61390
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow...
- Jul 22, 2026GHSA-w46p-w7w2-fr9gHighCVE-2026-65015
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature...
- Jul 22, 2026GHSA-h9fm-xcv2-qfw3MediumCVE-2026-65014
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}...
- Jul 22, 2026GHSA-4v35-78jc-648rMediumCVE-2026-65590
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux...
- Jul 22, 2026GHSA-88c4-pcqm-3r9pMediumCVE-2026-65596
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains"...
- Jul 22, 2026GHSA-h5xr-fqvj-253pHighCVE-2026-65592
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability...
- Jul 22, 2026GHSA-fxgw-9xvp-9r43LowCVSS 3.3CVE-2026-44187
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability...
- Jul 22, 2026GHSA-2jx7-9fh6-5m74MediumCVSS 6.5CVE-2026-16544
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for...
- Jul 22, 2026GHSA-6pxf-96xx-73mhMediumCVSS 6.5CVE-2025-13146
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary...
- Jul 22, 2026GHSA-6hm5-xxgq-f387HighCVSS 7.8CVE-2026-44190
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection...
- Jul 22, 2026GHSA-v5cc-389h-39x6MediumCVSS 6.6CVE-2026-44192
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This...
- Jul 22, 2026GHSA-6hcr-c36r-573wHighCVSS 8.1CVE-2026-4773
Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM...
- Jul 22, 2026GHSA-qqc6-9wv9-jxfpHighCVSS 7.8CVE-2026-44189
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's...
- Jul 22, 2026GHSA-2xmm-4jcc-wgxqMediumCVSS 4.3CVE-2026-16473
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame...
- Jul 22, 2026GHSA-fc5x-r66h-vp5fHighCVSS 8.8CVE-2026-14551
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions...
- Jul 22, 2026GHSA-7hfj-8497-9m6vunknownCVE-2026-63047
The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor...
- Jul 22, 2026GHSA-v36m-hw3w-whpwMediumCVE-2026-63264
The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product...
- Jul 22, 2026GHSA-fcfg-fr25-xwprMediumCVSS 6.5CVE-2026-2406
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer...
- Jul 22, 2026GHSA-qjw4-6j2q-9mgrCriticalCVE-2026-63048
The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload,...
- Jul 22, 2026GHSA-4r37-9m26-2c4mMediumCVSS 6.4CVE-2026-15787
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
- Jul 22, 2026GHSA-wpwx-q57v-jhwgunknownCVE-2026-12987
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration...
- Jul 22, 2026GHSA-4m7v-hj47-rqcrunknownCVE-2026-14322
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new...
- Jul 22, 2026GHSA-px8p-9vwx-vf98MediumCVE-2026-45820
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A...
- Jul 22, 2026GHSA-m254-gmq9-65xpunknownCVE-2026-12968
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does...
- Jul 22, 2026GHSA-cjff-5v28-x7h8HighCVSS 8.8CVE-2026-3821
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and...
- Jul 22, 2026GHSA-cjgw-jrh4-gfr3HighCVSS 8.1CVE-2026-15802
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to...
- Jul 22, 2026GHSA-g3hq-vgww-mrhjLowCVSS 5.5CVE-2026-16492
A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function...
- Jul 22, 2026GHSA-p58h-q4wh-jxrqLowCVSS 6.3CVE-2026-16490
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is...
- Jul 22, 2026GHSA-72f6-c934-4fg9HighCVE-2026-56844
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a...
- Jul 22, 2026GHSA-xj4j-jpm9-437junknownCVE-2026-16423
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who...
- Jul 22, 2026GHSA-37rv-54f5-xg5junknownCVE-2026-16420
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to...
- Jul 22, 2026GHSA-3jw8-qrmv-j8pjunknownCVE-2026-16422
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150...
- Jul 22, 2026GHSA-wrjj-v99g-x4f7MediumCVSS 4.3CVE-2026-63143
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via...
- Jul 22, 2026GHSA-c883-9873-x34junknownCVE-2026-16419
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed...
- Jul 22, 2026GHSA-8rg2-58vp-mq6wLowCVSS 4.3CVE-2026-16486
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects...
- Jul 22, 2026GHSA-5v5g-hvw6-x2x7MediumCVSS 6.5CVE-2026-63144
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially...
- Jul 22, 2026GHSA-r3rv-3hg4-3f4wLowCVSS 4.3CVE-2026-16485
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected...
- Jul 22, 2026GHSA-9pm3-74f7-q229MediumCVSS 4.3CVE-2026-63262
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information...
- Jul 22, 2026GHSA-727x-48vv-8cj7MediumCVSS 6.5CVE-2026-63263
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via...
- Jul 22, 2026GHSA-q5gv-xxq5-3m7cMediumCVSS 4.3CVE-2026-63145
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning...
- Jul 22, 2026GHSA-r356-68h4-gpq6unknownCVE-2026-16424
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote...
- Jul 22, 2026GHSA-qcp3-347v-7f6gMediumCVSS 6.5CVE-2026-63260
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
- Jul 22, 2026GHSA-jmgx-g6r2-c5f2unknownCVE-2026-16421
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a...
- Jul 22, 2026GHSA-qhc4-cxq6-mg2gLowCVSS 5.3CVE-2026-16489
A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function...
- Jul 22, 2026GHSA-j8w5-8rj6-wpwfLowCVSS 2.9CVE-2026-16517
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the...
- Jul 22, 2026GHSA-mq6c-w86q-vpp3MediumCVSS 5.0CVE-2026-63142
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with...
- Jul 22, 2026GHSA-vv4j-vm47-33w3MediumCVSS 4.3CVE-2026-63259
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information...
- Jul 22, 2026GHSA-95j6-2ch4-858wMediumCVSS 6.5CVE-2026-63261
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive...
- Jul 22, 2026GHSA-6mqg-64h7-88w3LowCVSS 5.0CVE-2026-16488
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the...
- Jul 22, 2026GHSA-76gg-4g7v-rm48unknownCVE-2026-16413
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker...
- Jul 22, 2026GHSA-9qpp-vgrg-5mhjCriticalCVE-2026-8984
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution...
- Jul 22, 2026GHSA-g3wx-h3f8-c23pCriticalCVE-2026-8985
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the ...
- Jul 22, 2026GHSA-245v-963x-ff5cCriticalCVSS 8.6CVE-2026-65318
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery...
- Jul 22, 2026GHSA-jx9v-4gxq-g867unknownCVE-2026-16414
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182...
- Jul 22, 2026GHSA-pfm9-xrwg-mf3rCriticalCVE-2026-8986
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when...
- Jul 22, 2026GHSA-vmf4-4c4w-vgqhCriticalCVSS 8.6CVE-2026-65317
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined...
- Jul 22, 2026GHSA-4cw2-m9qx-j82junknownCVE-2026-16417
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who...
- Jul 22, 2026GHSA-625r-xrww-9rxqHighCVSS 7.5CVE-2026-65319
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that...
- Jul 22, 2026GHSA-qpg5-v459-hjvjHighCVE-2026-8988
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that...
- Jul 22, 2026GHSA-wpf3-8j9v-2qg2HighCVE-2026-8989
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6...
- Jul 22, 2026GHSA-qh3x-7q6p-6x7fCriticalCVE-2026-8987
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the...
- Jul 22, 2026GHSA-mrwj-q3p7-wc59unknownCVE-2026-16418
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to...
- Jul 22, 2026GHSA-jc3p-7w2v-rw3cunknownCVE-2026-16415
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182...
- Jul 22, 2026GHSA-fp8j-cv93-rg46unknownCVE-2026-16416
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker...
- Jul 22, 2026GHSA-3xq5-vw38-q48pHighCVSS 7.8CVE-2026-62561
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal...
- Jul 22, 2026GHSA-v9mr-r78h-8w48MediumCVSS 6.5CVE-2026-62562
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal...
- Jul 22, 2026GHSA-597h-9gj7-c524MediumCVSS 5.4CVE-2026-62563
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component:...
- Jul 22, 2026GHSA-8gp2-77pc-xw4xHighCVSS 7.7CVE-2026-62560
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal...
- Jul 22, 2026GHSA-m95c-48mw-v3r3MediumCVSS 6.3CVE-2026-63141
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud...
- Jul 22, 2026GHSA-v5cg-c985-w5r3HighCVSS 7.7CVE-2026-62567
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)....
- Jul 22, 2026GHSA-5cp5-8443-8v7rHighCVSS 7.8CVE-2026-62574
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
- Jul 22, 2026GHSA-3rxg-g4hx-g2wmHighCVSS 7.1CVE-2026-62565
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll...
- Jul 22, 2026GHSA-qm4p-6mgx-rmgjMediumCVSS 4.3CVE-2026-65314
Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability...
- Jul 22, 2026GHSA-7359-rm9q-rghcHighCVSS 6.5CVE-2026-65316
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows...
- Jul 22, 2026GHSA-9hhj-2jwx-r87pHighCVSS 7.5CVE-2026-65315
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF...
- Jul 22, 2026GHSA-2vr9-rgv6-6m6qMediumCVSS 6.3CVE-2026-62528
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite ...
- Jul 22, 2026GHSA-788r-4vxm-prp9MediumCVSS 6.3CVE-2026-62524
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll -...
- Jul 22, 2026GHSA-3m63-63f7-w2ppHighCVSS 7.5CVE-2026-62521
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll -...
- Jul 22, 2026GHSA-w2mf-h36g-4f8hHighCVSS 8.1CVE-2026-62530
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French...
- Jul 22, 2026GHSA-cv5r-v7g9-545mHighCVSS 8.1CVE-2026-62547
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow...
- Jul 22, 2026GHSA-hj44-626j-fxwvMediumCVSS 6.3CVE-2026-62527
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component:...
- Jul 22, 2026GHSA-mjwv-5fmg-f43qMediumCVSS 6.5CVE-2026-62556
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal...
- Jul 22, 2026GHSA-9xcc-vx5q-8pf6MediumCVSS 6.3CVE-2026-62525
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality...